Docs / Setup Guide
Set up 9Secure.
Create a keyring, create or import your first vault, and complete your first local Sync.
Install and open 9Secure
- Get 9Secure from the download page.
- Open the app.
- Review the End-User License Agreement, then select Accept.
After the welcome screen, keep the default storage locations unless you need to change them, then select Create. Missing folders are created, and an existing keyring is not overwritten. This configures storage only; it does not create the keyring.
Scratch Folder is inside Keyring and Vaults Folder by default. 9Secure clears its contents when storage is confirmed and during cleanup. If you change it, use a dedicated private local folder outside cloud-synchronized storage, never a general-purpose folder.
Choose an accent color, select Continue, then continue past the welcome screen. iOS manages the storage locations.
Set up or import a keyring
A keyring protects the keys that unlock your vaults. Choose one path:
- Set Up Keyring creates a new keyring and Recovery Key.
- Import Keyring lets you select an encrypted
.9keyringarchive, enter its Keyring password, select Import, then unlock the imported keyring.
If you import, the password, Argon2id, device-unlock, creation, and Recovery Key sections below apply only to new keyrings.
Choose a keyring password
- Diceware creates a long passphrase from random words. The default five-word passphrase is rated Strong. Add words or select Reroll for a new passphrase.
- Structured creates compact, pronounceable segments with a number and uppercase letter. The default three-segment password is rated Strong. Add segments or select Reroll for a new password.
- Custom accepts your own password and requires confirmation. Use a long password that is unique to this keyring.
Diceware and Structured use the operating system's cryptographically secure random number generator. Save the selected password somewhere secure.
Four-digit PINs provide limited protection. They are better than storing sensitive information in plaintext notes, but a numeric PIN has only 10,000 possible combinations. It offers little resistance if an attacker obtains a copy of your keyring.
Keep the recommended Argon2id preset
Argon2id makes password guessing consume memory and time. Keep the preset marked Recommended.
The current recommendation on Windows and macOS is High.
The current recommendation on iOS is Medium.
Choose device unlock
Device unlock makes daily access faster but does not replace the keyring password or Recovery Key.
Leave Windows Hello on when available. It can use your face, fingerprint, or Windows PIN.
Leave Unlock with Touch ID, Face ID, or device password enabled if you want device-authenticated unlock.
Create your keyring
- Review the password, Argon2id preset, and device-unlock choice.
- Select Create Keyring.
Save your Recovery Key
The Recovery Key unlocks an existing keyring if you forget its password or lose device unlock. It cannot recreate missing keyring or vault files.
- Save the Recovery Key somewhere secure and separate from this device.
- Protect it like the keyring password. Anyone with the key and keyring file can unlock the keyring.
- Select Done.
You can view it again later from Keyring.
Create or import your first vault
A vault is an independent encrypted file and Sync boundary. Start with Personal. Add Work for work credentials and Media for large attachments. Sync Personal and Work where needed, and keep Media on storage-rich desktop devices unless another device needs it.
- Select New Vault, enter a name, and choose an icon.
- Choose one path:
- Select Import to bring in logins from a supported browser or password manager. Choose the provider, follow its export instructions, select Choose File, then select the exported file.
- Select Create to start with an empty vault, then:
- Open the vault and select New Item.
- Enter an item name and choose Login.
- Enter the Username and Website, then review or replace the generated Password.
- If the account uses TOTP, select Add Authenticator and paste its Base32 secret or
otpauth://totpURI. - Select Create and verify the saved fields and rotating code.
9Secure imports supported Login items and reports anything that must be recreated manually. Export files contain plaintext secrets, so delete the exported file after confirming the import.
Authenticator accepts a manual Base32 secret or a otpauth://totp URI. Manual secrets use SHA-1, six digits, and a 30-second period. TOTP URIs can use SHA-1, SHA-256, or SHA-512, six or eight digits, and a period from 1 through 300 seconds. HOTP is not supported.
Other item types include Payment Card, Bank Account, Address, Identity / Passport, Software License, WiFi Network, Crypto Wallet, API Credential, SSH Key, Secure Note, File, and Custom. Each type provides fields suited to that information.
Authenticator and passkeys are extensions of a Login, not separate item types. See Items and Credentials for passkey setup, the complete item list, and SSH Key commands.
Complete platform access
On macOS, select Enable for Vaultlight Accessibility on the welcome screen or in Settings. It is required for Paste, Type Out, and global Escape.
Press Ctrl+; to open Vaultlight. Search for the Login, select it, then use Ctrl+1 through Ctrl+0 to deliver its fields. By default, Vaultlight pastes the field into the app that was active before it opened. Change the shortcut and delivery behavior in Settings.
Open Settings, find Password AutoFill, select Open Settings, and enable 9Secure in iOS. Return to 9Secure, select Refresh, then verify the saved Login appears in an app or website login field.
Complete your first Sync
- Open Sync on two unlocked, awake devices connected to the same local network.
- Turn on Sync on both devices and allow local-network access if prompted.
- Select Pair a Device or Pair Device on both devices, then select the discovered device.
- On one device, select the number shown on the other, then select Confirm on both devices.
- Enable the vault under the paired device and select Sync or Sync All.
- Open the vault on the receiving device and verify the Login.
See the Sync guide for vault subscriptions, deletion, and troubleshooting.
Finish setup
- Open Sentinel, select Run Audit, and review the findings.
- Read Security Architecture before exporting keys, exporting vaults, or using Archive Keyring.
- For backups, select Lock first, copy the encrypted vaults and keyring, then test the copies. On Windows, closing the window may only hide or minimize 9Secure; use Lock or fully quit from the system tray.
- iOS can export encrypted vault copies from Keyring, but it has no non-destructive active-keyring backup action. Archive Keyring removes the active keyring and is not a routine backup.
- Sync is not a backup. Lock 9Secure when finished.